Skip to content

v2.2.0

Choose a tag to compare

@alsekaram alsekaram released this 30 Sep 18:22
· 3 commits to main since this release
40feadf

Security release.

Fixes

  • Sync client proxy was bypassed. The proxy was passed to requests as a bare string, which it silently ignores, so requests went out directly from the real IP. It is now passed as a {"http": ..., "https": ...} mapping.
  • Off-by-one in Proxy.get_random_proxy: it could pick a port outside the configured range.
  • Private keys are no longer shown in repr(Account).
  • Async requests no longer log request data, and a debug print in NodeException was removed.

New

  • expected_chain_id parameter: transactions are signed only if the node reports this chain id.
  • set_abi(code, abi): use a trusted local ABI instead of the one served by the node.
  • rpc_host is validated: it must be an http(s) URL, and plain HTTP to a non-local host emits a warning.

Breaking changes

  • Async requests now raise NodeException on any non-2xx response, as the sync ones do. Before, they returned the error body.
  • An rpc_host without a scheme now raises ValueError.

Dependencies

Raised minimum versions: aiohttp>=3.12.14, requests>=2.32.4, pycryptodome>=3.19.1.

Install: pip install -U eosapi-async==2.2.0